CVE-2005-1332
- EPSS 1.3%
- Published 04.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.
- EPSS 4.72%
- Published 04.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitrary files.
CVE-2005-1335
- EPSS 0.48%
- Published 04.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner."
CVE-2005-1336
- EPSS 0.08%
- Published 04.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable.
CVE-2005-1337
- EPSS 0.55%
- Published 04.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.
CVE-2005-1338
- EPSS 0.07%
- Published 04.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store initial LDAP passwords for new accounts in plaintext.
CVE-2005-1339
- EPSS 0.64%
- Published 04.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.
CVE-2005-1340
- EPSS 0.64%
- Published 04.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabled, which allows remote attackers to use the proxy.
CVE-2005-1341
- EPSS 0.85%
- Published 04.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences.
CVE-2005-1342
- EPSS 17.7%
- Published 04.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The x-man-page: URI handler for Apple Terminal 1.4.4 in Mac OS X 10.3.9 does not cleanse terminal escape sequences, which allows remote attackers to execute arbitrary commands.